nerdexam
(ISC)2

CGRC · Question #546

What are the nine steps of Risk Assessment Methodology? Response:

The correct answer is A. 1 - System Characterization. The first step in a typical risk assessment methodology, such as those outlined by NIST, is System Characterization. This involves defining the scope, boundaries, and characteristics of the system to be assessed.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What are the nine steps of Risk Assessment Methodology? Response:

Options

  • A1 - System Characterization
  • B1 - Impact Analysis
  • C1 - System Characterization
  • D1 - Control Analysis

How the community answered

(31 responses)
  • A
    87% (27)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The first step in a typical risk assessment methodology, such as those outlined by NIST, is System Characterization. This involves defining the scope, boundaries, and characteristics of the system to be assessed.

A1 - System CharacterizationCorrect

In most widely accepted risk assessment methodologies, including NIST SP 800-30, the initial and foundational step is System Characterization. This step involves a thorough understanding and documentation of the system's mission, functions, architecture, data types, and operating environment. Clearly defining these characteristics ensures that the subsequent risk identification and analysis steps are performed within a precise and relevant context, forming the basis for an effective assessment.

B1 - Impact Analysis

Impact Analysis is typically performed after system characterization and threat identification to determine the consequences of adverse events, not as the first step.

C1 - System Characterization
D1 - Control Analysis

Control Analysis involves reviewing existing security controls, which occurs after risks have been identified, not as the initial step in the methodology.

Concept tested: Risk assessment methodology steps

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Risk Assessment Methodology#NIST SP 800-30#System Characterization#Risk Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice